Showing posts with label Cybersecurity Education. Show all posts
Showing posts with label Cybersecurity Education. Show all posts

Friday, January 30, 2026

Review – HR 6631 Introduced – DOD Cybersecurity Education

Earlier this month Rep Elfreth (D,MD) introduced HR 6631, the Establishing Cyber Security Educational Programs at Academic Institutions Act. The bill would require DOD to collaborate with academic institutions to develop cybersecurity educational programs at such institutions. Collaboration with other federal agencies would ensure that the program would not compete or conflict with other such federal programs. No new funding is authorized.

Moving Forward

Both Elfreth and her sole cosponsor, Rep Luttrell (R,TX) are members of the House Armed Services Committee to hic this bill as assigned for consideration. This means that there may be sufficient influence to see the bill considered in Committee. I see nothing in the bill that would engender any organized opposition, and I would suspect that there should be bipartisan support for the legislation. We will have to wait and see if there is sufficient bipartisan support for the bill to be considered by the full House under the suspension of the rules process.

Commentary

While subsection 2(a) requires DOD to “develop cybersecurity [emphasis added] educational programs”, paragraph 2(c)(1) expands that scope to include “cyber defense, cyber operations, and cyber research”. This should be expected of a DOD sponsored program and would differentiate the overall program from those sponsored by other federal agencies. While graduates of these DOD programs could be expected to seek out DOT related jobs, or military commissions, the skills learned could still be applicable to civilian cybersecurity positions.

 

For more information on the provisions of this bill, including additional commentary on OT coverage, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-6631-introduced-dod-cybersecurity - subscription required.

Thursday, June 15, 2023

Review - HR 3429 Introduced – Cybersecurity Education Support

Last month, Rep Lieu (D,CA) introduced HR 3429, the New Collar Jobs Act of 2023. The bill would provide employer incentives to provide cybersecurity training to employees and would provide federal loan forgiveness to certain individuals student loans. No new spending is authorized by this bill. The bill is virtually identical to HR 4389 which was introduced last session by Lieu. No action was taken on that bill.

Moving Forward

Lieu is a member of the House Science, Space, and Technology Committee to which this bill was assigned for primary consideration. This means that there may be sufficient influence to see the bill considered in Committee. While no spending is authorized by the bill, the loan forgiveness provisions may draw the ire of the Republican budgetary-hawks, so there may be some organized opposition for that reason. I suspect that there would be some bipartisan support for the bill, but not enough to see the bill considered under the suspension of the rules process if it were to make it to the floor of the House. That means that the bill would not likely be considered by the House because of the influence of the conservative minority on the Rules Committee.

Commentary

While there are no specific mentions of control system cybersecurity in the legislative requirements, two of three congressional findings in §2 of the bill address manufacturing control system security issues. Thus the ‘congressional intent’ clearly applies (not exclusively, to be sure) the education support provisions to control-system-security educational programs.

 

For more details about the provision of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-3429-introduced - subscription required.

Wednesday, November 2, 2022

Review - HR 9085 Introduced – Cybersecurity Clinics

In September, Rep Veasey (D,TX) introduced HR 9085, the Cybersecurity Clinics Grant Program Act. The bill would require CISA to establish a new “Cybersecurity Clinics Grant Program”. The grants would be used to fund university-based cybersecurity clinics at community colleges and minority serving educational institutions. The bill would authorize such funding as necessary to carry-out the grant program.

Moving Forward

Veasy is not a member of the House Education and Labor Committee to which this bill was assigned for consideration. This means that there is not likely to be sufficient influence to see this bill considered in Committee. While I see nothing in this bill that would engender any organized opposition to the bill, it is so vaguely worded that there would likely not be enough support for the bill to carry it through the Committee to the floor of the House were it to be considered.

This looks very much like an election year “see I am doing something about cybersecurity education” type legislation.

Commentary

This is a weak bill, with no provisions concerning the administration of the grant program and no indication about how much money CISA would be expected to provide in the grants. The conflicting requirements for CISA to provide an undefined ‘experiential cybersecurity curriculum’ while requiring the agency to provide guidance to schools on how to develop the same curriculum shows how poorly thought out this proposed program really is.

 

For more details about the provisions of this legislation, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-9085-introduced - subscription required.


Wednesday, January 26, 2022

Review – S 2305 Reported in Senate – Cybersecurity Education Grants

Earlier this month, the Senate Homeland Security and Governmental Affairs Committee published their report on S 2305, the Cybersecurity Opportunity Act. The Committee met on August 4th, 2021 to consider the bill. Substitute language was offered and amended before the Committee adopted the new language. The bill would now require at least 50% of  grant funds released under this program to go to “historically Black colleges and universities and minority-serving institutions” and added a five year sunset provision for the grant program. No spending authorization was added to the bill.

The bill is now cleared for consideration by the full Senate. This bill is unlikely to come to the floor under regular order, it is just not politically important enough to consume that type of time. There is a possibility that this bill could be considered under the Senate’s unanimous consent process, but a single Senator could block that consideration. A more likely possibility would be for the bill to be added to some larger, more important bill as part of the amendment process. If the bill were to be considered on its own under regular order, I would expect the bill to receive significant bipartisan support.

For more information about the changes made in the language of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-2305-reported-in-senate - subscription required.

Thursday, October 21, 2021

HR 5593 Introduced - Cybersecurity Opportunity

Last week, Rep Johnson (D,GA) introduced HR 5593, the Cybersecurity Opportunity Act. This bill is nearly identical in intent to S 2305 introduced by Sen. Ossoff in June. This version is legislatively more complex but it would still have required DHS to “award grants to assist institutions of higher education that have an enrollment of needy students, historically Black colleges and universities, and minority-serving institutions, to establish or expand cybersecurity programs, to build and upgrade institutional capacity to better support new or existing cybersecurity programs.”

Johnson was not a member of either the House Education and Labor or Homeland Security Committee to which this bill was assigned for consideration. Of the 40 cosponsors, however, 10 are members of the House Homeland Security Committee and five are members of the Education and Labor Committee. This should mean that there would be adequate influence to see this bill considered in Committee. I see nothing in this bill that would engender any specific opposition. I suspect that the bill would receive at least some measure of bipartisan support even without any Republican cosponsors.


Friday, December 13, 2019

Bills Introduced – 12-12-19


Yesterday with both the House and Senate in session there were 55 bills introduced. Of those three may receive additional coverage in this blog:

S 3033 A bill to establish a K-12 education cybersecurity initiative, and for other purposes. Sen. Peters, Gary C. [D-MI]

S 3040 A bill to amend the Higher Education Act of 1965 to include teacher preparation for computer science in elementary and secondary education. Sen. Rosen, Jacky [D-NV] 

S 3045 A bill to amend the Homeland Security Act of 2002 to protect United States critical infrastructure by ensuring that the Cybersecurity and Infrastructure Security Agency has the legal tools it needs to notify private and public sector entities put at risk by cybersecurity vulnerabilities in the networks and systems that control critical assets of the United States. Sen. Johnson, Ron [R-WI]

Cybersecurity Education


Actually, I doubt that S 3033 and S 3040 will contain language specifically including control system security processes in the required curriculum. That would normally mean that I would not cover these bills here. So I will take this opportunity to get a screed about K-12 education out of my system.

Students are in the K-12 education environment for 13 years for something like 9 months out of the year. A typical school day (minus extracurricular activities) last six to eight hours. In that brief time students are exposed to the basic knowledge necessary for participation in our society. Back in the dark ages when I went to school that consisted of reading, writing, arithmetic, foreign language, history and the arts with a smattering of physical education. Each year the components of those basics became more complex, building on the previous knowledge gained. And the school day was rather full.

Whenever we add new curriculum to that base, decisions have to be made about where the time for teaching the new material will be added. We could increase the number of hours at school, but that would cut into extracurricular activities and besides students can only be expected to take so much time sitting around learning. The alternative it to reduce the time it takes to teach the other subjects or to remove some of those subjects.

It would seem to me that anytime we legislatively attempt to expand the required knowledge base we must also determine where the time will come from to add that instruction. Unfortunately, congresscritters are notorious for adding program requirements without adding resources to effect those requirements. Just let the affected managers make the hard decisions. That way the complaints will be focused on them not congresscritters.

CISA Subpoenas


S 3045 has been in the works for a while now. I have not yet seen the bill, but press accounts (see here for instance) make this seem like a good idea. It would apparently give CISA that power to issue subpoenas to Telecoms to require them to provide contact information for internet addresses where CISA has identified a critical infrastructure vulnerability. That would allow CISA to contact the vulnerable party and work with them to mitigate the vulnerability. Motherhood and Apple Pie, who can object to that? Of course, the devil is in the details.

Thursday, March 28, 2019

HR 1592 Introduced – Cybersecurity Training


Earlier this month Rep. Langevin (D,RI) introduced HR 1592, the Cybersecurity Skills Integration Act. The bill would establish a grant program within the Department of Education to provide support to post-secondary education programs that incorporate cybersecurity training or integrate cybersecurity training into existing education programs.

Definitions


Section 3(h) establishes the definitions used in this bill. The key definition in the bill is for the term ‘cybersecurity education’; it is defined as “education about ensuring the confidentiality, integrity, availability, and safety of information systems used in critical infrastructure sectors, including control systems and operational technology” {§3(h)(2)}.

Grant Program


Program grants of up to $500,000 per year may be made under this program. The bill provides for $10 million to be authorized to support the grant program {§(g)}. There is no time limit on that authorization in the language of the bill.

Moving Forward


While Langevin is not a member of the House Education and Labor Committee, the committee to which the bill was assigned for consideration, one of his cosponsors, Rep. Thompson (R,PA), is a senior member of the Committee. This means that there may be enough influence to see this bill covered in Committee.

There are no provisions in the bill that would draw any serious opposition to the bill. The main impediment to passage will be the price tag.

Commentary


The general idea that cybersecurity needs to be a topic included in degree and certification programs other than computer science certainly is one worthy of discussion. Money is, of course, one of the impediments to achieving that goal, but it is only one of the problems. The other is that there are only so many classroom hours available in degree programs and adding any new classes mean that something else has to be given up to make room in the schedule.

As should be expected by most readers, I have some problems with the cybersecurity definition used in this bill. I have to acknowledge that the staffers who wrote this bill made an honest effort to ensure that industrial control system cybersecurity issues would be addressed by this grant program. As fairly usual, however, they have taken information technology language (in this case the standard ‘confidentiality, integrity and availability’ measure of security and tacked onto the end ‘including control systems and operational technology’. The fact that the CIA security standards are not directly applicable to control system security is of little matter.

It would be helpful if there were a clear delineation that different types of cybersecurity training are going to be applicable to different types of degree programs. Most students in business and liberal arts programs are going to find information technology security classes most helpful. Students in science and engineering programs, however, are going to be more concerned about protecting physical systems rather than information from cyber-attacks.

Having said that, of course, all students need some basic cyber hygiene training; passwords, two-factor authentication, phishing, etc. I am not sure, however, that these need to wait until post-secondary education. It seems to me that these types of training would be more appropriate in elementary or middle school given the widespread use of cellphones and tablets by people in that age groups.

Friday, March 8, 2019

Bills Introduced – 03-07-19


Yesterday with both the House and Senate preparing to leave for the weekend there were 117 bills introduced. Three of those bills may receive additional coverage in this blog:

HR 1589 To amend the Homeland Security Act of 2002 to establish chemical, biological, radiological, and nuclear intelligence and information sharing functions of the Office of Intelligence and Analysis of the Department of Homeland Security and to require dissemination of information analyzed by the Department to entities with responsibilities relating to homeland security, and for other purposes. Rep. Walker, Mark [R-NC-6] 

HR 1592 To direct the Secretary of Education to establish a pilot program to award competitive grants for the integration of cybersecurity education, and for other purposes. Rep. Langevin, James R. [D-RI-2]

S 715 A bill to improve the productivity and energy efficiency of the manufacturing sector by directing the Secretary of Energy, in coordination with the National Academies and other appropriate Federal agencies, to develop a national smart manufacturing plan and to provide assistance to small- and medium-sized manufacturers in implementing smart manufacturing programs, and for other purposes. Sen. Shaheen, Jeanne [D-NH] 

Most past legislative references to CBRN intelligence have focused on ‘biological’ issues as I suspect that HR 1589 will. Still I will cover this bill because the bill will mandate ‘chemical’ intelligence sharing even if that is not the focus.

HR 1592 will be followed here if it contains specific mention of industrial control system cybersecurity education.

Shaheen’s previous ‘smart manufacturing’ bills have not addressed cybersecurity concerns. We will have to see if this changes with this bill.

Tuesday, December 4, 2018

Bills Introduced – 12-03-18


With both the House and Senate in session yesterday, there were 14 bills introduced. I will be watching three of these in the short time left in the 115th Congress:

HR 7213 To amend the Homeland Security Act of 2002 to establish the Countering Weapons of Mass Destruction Office, and for other purposes. Rep. Donovan, Daniel M., Jr. [R-NY-11]

HR 7214 To direct the Secretary of Education to establish a pilot program to award competitive grants for the integration of cybersecurity education, and for other purposes. Rep. Langevin, James R. [D-RI-2]

HJ Res 143 Making further continuing appropriations for fiscal year 2019, and for other purposes. Rep. Frelinghuysen, Rodney P. [R-NJ-11]

HR 7213 is a perennial favorite, but I suspect this version is unique in that it would include CISA language. I am interested in this bill for possible provisions concerning chemical weapons and more importantly the weaponization of industrial chemicals.

HR 7214 looks like an interesting concept from a Congressman noted for his interest in cybersecurity issues. Note: he will be a tad bit more important next year in the Democratic House and this bill will almost certainly reappear then.

HJ Res 143 is a two-week continuing resolution that continues funding those portions of the Government without a passed funding bill (principally DHS and State) until December 21st, 2018. Ostensibly this is required because the House and Senate will be honoring the late President HW Bush today and tomorrow and they will not be able to work on the actual spending bill during that time. This is a relatively ‘clean’ CR as the only added provision is a similar extension of the flood insurance program. This bill will be passed in the House on Thursday and either Thursday or Friday in the Senate.

NOTE: Only HJ Res 143 will see any action in this session; the other two are ‘look what I have done’ bills.

Wednesday, July 26, 2017

Bills Introduced – 07-25-17

Yesterday with both the House and Senate in session, there were 34 bills introduced. Of those, two may be of specific interest to readers of this blog:

HR 3393 To increase cybersecurity education and job growth, and for other purposes. Rep. Lieu, Ted [D-CA-33]

S 1631 A bill to authorize the Department of State for Fiscal Year 2018, and for other purposes. Sen. Corker, Bob [R-TN]

HR 3393 will only receive additional coverage here if the definitions used in the bill are inclusive of control system security education programs.


 I will be watching (but not holding my breath) S 1631 to see if it includes any cybersecurity provisions.

Wednesday, March 29, 2017

Bills Introduced – 03-28-17

With both the House and Senate in session yesterday there were 43 bills introduced. Of those one may be of specific interest to readers of this blog:

S 754 A bill to support meeting our Nation's growing cybersecurity workforce needs by expanding the cybersecurity education pipeline. Sen. Markey, Edward J. [D-MA]


It will be interesting to see what definitions are used in this bill to outline the scope of cybersecurity workforce. If the language is inclusive of industrial control systems then there will be further mention of this bill in this blog.

Tuesday, January 20, 2015

HR 53 Introduced – Cybersecurity Education

As I reported in an earlier post Rep. Jackson-Lee (D,TX) introduced HR 53, the Cyber Security Education and Federal Workforce Enhancement Act. This bill would formally establish the current the Cybersecurity Education and Awareness Branch (CEA) within the Department of Homeland Security’s (DHS) Office of Cybersecurity and Communications (CS&C). The CEA manages the National Initiative for Cybersecurity Careers and Studies (NICCS).

This program in DHS is not specifically mentioned in the Explanatory Statement that accompanied HR 240 (the current DHS funding bill). Presumably the funding for this program comes out of the $15 million for education listed under ‘Global Security Management’. This bill would do nothing to increase that funding, but might raise the level of visibility to the point where it might get mentioned in the future.

The programs identified in the bill would help foster federal cybersecurity workforce development. There would certainly be some spillover effect into the private sector as personnel moved out of the government and the education programs produced cybersecurity trained personnel excess to the government needs.


If Ms. Jackson-Lee can convince the Republican leadership in three committees (Homeland Security, Science and Technology, and Education and Workforce) to consider this bill then the bill might make it to the floor in the House. There is nothing in the bill that would seem to inspire specific opposition, so it would probably pass if considered.
 
/* Use this with templates/template-twocol.html */